CEO fraud is a payment fraud in which an attacker impersonates a senior executive to authorize a transfer or a change to payment details. It is a subtype of business email compromise, and the impersonation now arrives by voice and video as often as by email. The target is almost always the person who processes the request rather than the executive being impersonated.
What fails is an assumption rather than a technology: almost every approval chain takes it for granted that the requester’s identity was established before the request reached finance.
What the attack actually looks like
The request is designed to be plausible and to close quickly.
It comes from someone with the authority to ask. A CEO, CFO, or finance director, or a lawyer or acquirer acting for them. That is what removes the natural friction: querying it means questioning a superior.
It is time-boxed and quiet. A deal that must close today, a supplier who will halt shipment, a transaction to be kept confidential until an announcement. Confidentiality is doing real work in these scripts, because it removes the sideways check with a colleague that would end the attack.
It arrives through a channel that carries authority. A real mailbox after an account takeover, a lookalike domain, a phone call with a cloned voice, or a video call.
It asks for one of three things: release a payment, change a vendor’s bank details, or change payroll deposit details. The second is the most durable, because it redirects future payments as well as the current one.
In the 2024 Arup case, a finance employee joined a video conference where the CFO and every other participant was synthetic, and approved roughly $25 million across 15 transfers (CNN / FT, May 2024). The employee did the sensible thing by seeking confirmation on a call. The call was the attack.
Why voice and video stopped settling the question
Recognizing a voice used to be reasonable evidence. McAfee researchers, testing freely available tools, produced a clone with an 85% voice match from three seconds of audio in one test, and reached a 95% match after training on a small number of files (McAfee Labs, 2023). In the same research, 70% of people said they were not confident they could tell a cloned voice from the real thing (McAfee Labs, 2023).
Executives are the easiest people in the organization to clone. Earnings calls, conference panels, podcasts, and company videos put minutes of clean audio in public.
Video is no safer. In a 2025 iProov study of 2,000 US and UK consumers, only 0.1% correctly identified every real and fake sample, and high-quality deepfake video was caught 24.5% of the time even when participants were told to look for fakes (iProov, 2025).
The scale
The FBI’s Internet Crime Complaint Center recorded business email compromise at 24,768 complaints and $3,046,598,558 in 2025, an average near $123,000 per incident, with 86% of losses moving by wire or ACH (FBI IC3, 2025 Annual Report, pp7–10). Total reported losses across all categories reached $20.877 billion, up 26% year over year (FBI IC3, 2025, p6).
The wire-and-ACH figure is the one to plan around. The money leaves through a payment process, approved by a person who believed the request was legitimate, rather than through any technical exploit.
Speed compounds it. Trusona’s finance materials describe a $1.2 million wire released in 31 seconds. The window for catching one of these after approval is short, and recovery of an executed international wire is often impossible.
Why the usual finance controls do not catch it
Dual authorization requires two approvals of the same request. If both approvers received the same convincing instruction, both approve. Dual control protects against one person acting alone, not against two people being deceived identically.
Approval thresholds define which payments need extra scrutiny. Attackers read the thresholds from behaviour and request amounts underneath them, or split the transfer, which is what 15 transfers rather than one looks like.
Callback verification is the right instinct and it has a specific hole. Calling back the number in the email verifies nothing. Calling back the number on file fails when the number has been SIM-swapped, and CISA lists SIM swap among these groups’ core techniques (CISA, advisory AA23-320A). It also fails when the attacker anticipates the callback and answers.
Email authentication stops spoofed domains and does nothing about a genuine mailbox that has been taken over, or about a phone call.
Training tells staff to be suspicious of unusual requests. Vendor bank detail changes are ordinary work.
A verification procedure finance can run
The aim is a check that does not depend on recognizing a person, and that a clerk can complete without needing to challenge an executive’s authority.
1. Define the trigger events, in writing. Verification is required for: any change to vendor bank details, any change to payroll deposit details, any first payment to a new beneficiary, and any transfer above a threshold your treasury team sets. Trigger on the event, never on how unusual the request feels.
2. Verify on a separate channel that you initiate. The requester must be reached through a route your organization already holds, never through a reply, a number supplied in the request, or a link in the message.
3. Verify the person, not the channel. A callback proves someone answered a number. Where the amount or the change justifies it, verify identity directly: have the requester confirm through a check against an authoritative source, such as a government-issued ID verified against the authority that issued it. That tests a record the attacker cannot alter, unlike a voice or a knowledge answer.
4. Check whether the number moved. SIM swap and port-out detection tells you whether the phone you are calling back changed hands recently. It is the single most useful fact on a callback and it lives with the carrier, not in your records.
5. Enforce a settling period on bank detail changes. A mandatory delay between a change and the first payment against it, with notification to the previously known contact. Most of these frauds depend on the change and the payment happening in the same session.
6. Make the check unskippable and blameless. Write down that no one may waive it, including the CEO, and say so publicly before it is ever needed. A control that a sufficiently senior voice can override is not a control. Staff need to know that pausing a payment is the correct outcome and will never be held against them.
7. Measure the override rate. If verification is bypassed on 6% of qualifying payments, your coverage is 94% and attackers will find the rest.
If a payment has already gone out
The first hours decide whether any of it comes back, and the sequence is not intuitive.
Call the bank before anything else. Ask specifically for a SWIFT recall on an international wire, or a reversal request on an ACH. Do this before internal escalation, before legal, and before assembling facts. Funds move through intermediary accounts quickly, and a recall attempted the same day has meaningfully better odds than one attempted the next morning.
File with IC3 the same day. The FBI’s Internet Crime Complaint Center operates a recovery process for fraudulent domestic wires that can freeze funds where reporting is fast. It works on hours, not days.
Contact the receiving institution directly, in parallel rather than in sequence. The sending bank’s recall request and a fraud report from the victim organization reach different desks.
Preserve the evidence before cleaning up. Keep the original messages with full headers, the call records, the meeting invitation, and the approval trail. If the request came through a compromised mailbox, that mailbox is now an investigation subject and should not be tidied.
Assume the account is still compromised. A successful payment fraud usually means either an account takeover or a convincing external impersonation. If it was a takeover, the attacker still holds access, along with any forwarding rules or delegate permissions they added, and a second request is a realistic next step. Revoke sessions rather than only changing the password.
Warn the people who will be targeted next. Vendor bank detail fraud tends to arrive at several customers of the same supplier. Finance and AP teams elsewhere in your supply chain benefit from knowing quickly.
Then run the post-mortem on the process rather than the person. If a clerk approved a payment on a convincing instruction from a cloned executive voice, the control that failed was the absence of a verification step, not the clerk’s judgment.
The reverse check for executives
There is a version of this aimed at executives directly: a call or video conference from a peer, a board member, or an advisor requesting an approval, a document, or a confidential decision.
Exec Verify covers that direction: one executive confirming another’s identity before money moves or sensitive information changes hands. The principle is the same as the finance procedure: the person receiving the request gets a way to check, instead of being asked to trust what they hear.
The governance case for treating authority itself as an attack surface is argued in AI deepfakes and executive impersonation.
ATO Protect verifies the person behind a request against the authority that issued their ID, in real time, with no pre-registration and no app to install, and adds SIM swap and port-out detection plus patented man-in-the-middle and anti-replay detection (US Pat. 10,601,859). See ATO Protect for Finance and Agent Verify.
Frequently asked questions
What is CEO fraud? CEO fraud is a payment fraud in which an attacker impersonates a senior executive to authorize a transfer or a change to payment details. It is a subtype of business email compromise. The target is the person who processes the payment rather than the executive being impersonated.
What is the difference between CEO fraud and business email compromise? CEO fraud is one form of BEC, specifically the one that impersonates a senior executive. BEC also covers vendor invoice fraud, payroll diversion, attorney impersonation, and data theft requests. The FBI recorded 24,768 BEC complaints and $3.05 billion in losses in 2025.
How do you verify a wire transfer request? Verify on a channel you initiate, never one supplied in the request, and verify the person rather than the channel. Where the amount justifies it, check identity against an authoritative source such as a government ID verified with its issuing authority, and check whether the callback number was recently SIM-swapped. Trigger verification on defined events, such as any bank detail change, rather than on how suspicious a request feels.
Why do callback procedures fail? Because a callback confirms that someone answered a phone number, not who they are. Calling a number supplied in the request reaches the attacker. Calling the number on file fails if it has been SIM-swapped or port-out fraud has moved it, and attackers anticipate callbacks and answer them.
Can deepfakes really pass a video call? Yes. In the 2024 Arup case a finance employee joined a video call where the CFO and every other participant was synthetic, and approved roughly $25 million across 15 transfers. In a 2025 iProov study, high-quality deepfake video was correctly identified 24.5% of the time even by people told to look for fakes.
Does dual authorization prevent CEO fraud? Not reliably. Dual authorization protects against one person acting alone. If both approvers received the same convincing instruction, both approve. It should be paired with identity verification of the requester.
What is executive impersonation? Any attack in which someone poses as a senior leader to obtain money, information, or access. CEO fraud is the payment-focused form. It also covers requests for confidential documents, credentials, or approvals that bypass normal process.
How quickly can money be lost? Very quickly. Trusona’s finance materials describe a $1.2 million wire released in 31 seconds. Recovery of an executed international wire is frequently impossible, which is why the control has to sit before approval rather than in detection afterwards.
Every one of these frauds ends with a legitimate employee doing their job correctly, on the strength of an identity nobody checked. That check is the entire control.
Exec Verify confirms the executive before the wire moves.